Skip to content
SecPod  – Documentation
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
Search this website
Menu Close
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO

Saner Platform

  • Saner Platform Release Notes
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
  • Saner Platform Guide
    • Saner Platform Function Guides
    • Saner Device Management User Guide
  • How Tos
    • General
      • How to increase the subscription count for an Account in Saner CVEM
      • How to increment license count for an Organization in Saner CVEM
      • How to provision Saner tools for an Organization
      • How to change subscription type in Saner CVEM
      • How to sign-up with Saner CVEM?
      • How to create a new account in Saner CVEM?
      • How to create a new user in Saner CVEM?
      • How to enable SSO authentication policy in Saner CVEM?
      • How to set alerts in SanerNow?
      • How to view, download and filter the audit logs?
      • How to designate Saner Agent to perform network scan?
      • How to Co-Brand with your logo?
      • How to fetch the details of the mandatory fields from the Okta account?
      • How to create MFA policy for Okta?
      • How to fetch the details of the mandatory fields from the PingID account?
      • How to create MFA policy for PingID?
      • How to fetch the details of the mandatory fields from the PingOne account?
      • How to create MFA policy for PingOne?
      • How to download and install Saner Agent in Mac?
      • How to download and install Saner agent in Linux?
      • How to download and install the Saner agent in Windows?
      • How to update the expiry date of an existing subscription?
      • How to manage users and their preferences using role-based access?
      • How to uninstall SanerNow Agent using SanerNow Offline deployer tool.
      • How to onboard a new organization?
      • How to deploy SanerNow Agent using SanerNow Offline deployer tool.
      • How to install a Saner agent through the command line?
      • How to uninstall the Saner agent through command line?
    • Saner Reports
      • How to configure mail settings to email Report PDF?
      • How to create a custom report in SanerNow?
      • How to schedule for the report back up?
    • Saner Device Management
      • How to create custom groups in Saner CVEM
    • Saner Mail Settings
      • How to create new mail settings in Saner?
      • How to use OAuth-enabled authentication in Saner mail settings
      • How to create OAuth Client ID and Client Secret for Gmail
      • How to create OAuth Client ID and Client Secret for Microsoft 365.
  • FAQs
    • Saner CVEM Technical FAQs
  • Supported OSs and Platforms
    • Operating Systems and Platforms Supported
    • Supported Third-party Applications for Patching

Saner Cloud

  • Before You Begin
    • Glossary of Terms
    • Read me First
  • Get Started
    • Saner Cloud Deployment Guides
      • Azure Onboarding
      • Troubleshooting
      • Get Started with Saner CNAPP AWS Cloud Deployment V1.0
      • Onboarding with AWS Credentials(Least Recommended Method)
      • Onboarding with AWS Role(Manual)
      • Onboarding with AWS Role CloudFormation (Automatic): Recommended
    • Roles and Permissions
      • Roles and Permissions for AWS Remediation Access
      • Roles and Permissions for Azure Onboarding, Detection, and Remediation
  • Learn About
    • Excessive Permission Categories Evaluated Across Different Cloud Services
    • Publicly Accessible Resources
    • Patch Aging and Patch Impact
    • SecPod Default Benchmarks
    • Watchlists
    • Cloud Workload Protection Platform(CWPP)
    • Overview of Report Views in Saner Cloud
    • Whitelisting Resources
    • Saner Plasma AI Assistant for Seamless User Interaction
    • Critical Events to Monitor in AWS
    • High-Privilege Actions in Critical Activity Logs for AWS
    • Audit Logs in Saner Cloud
    • Excessive Permissions
    • Alerts in SanerCloud
  • User Guides
    • Cloud Security Remediation Management(CSRM) User Guide
    • Cloud Infrastructure Entitlement Management(CIEM) User Guide
    • Cloud Security Posture Anomaly(CSPA) User Guide
    • Cloud Security Asset Exposure(CSAE) User Guide
    • Cloud Security Posture Management(CSPM) User Guide
  • Tell Me How
    • How to Configure Automation Rule to Remediate Misconfigurations?
    • How to Manage Report Views at Organization-level in Saner Cloud?
    • How to Get a Cohesive View from Saner Cloud Unified Dashboard?
    • How to Use Tags to Quickly Filter Resources?
    • How to Troubleshoot Issues with Audit Logs?
    • How to Manage Groups and Tags in Saner Cloud?
    • How to Manage Report Views for a User Account in Saner Cloud?
    • How to Troubleshoot or Analyze with Critical Activity Logs?
    • How to Setup Alerts Across SanerCloud Tools?
    • How to Take Action on Alert Notifications from SanerCloud?
    • CIEM
      • How to See the Active Version for an IAM Policy?
      • How to Troubleshoot or Analyze with Critical Activity Logs?
      • How to View by Type and Usage for any Identity in CIEM?
      • How to Get Visibility into Cloud Entitlements?
      • How to Use Evidence to Address Policies with Excessive Permission?
      • How to Know the Excessive Permissions on a Specific Service?
      • How to Visually See the Relationship between Identity, Entitlement, Policy, or Permission?
      • How to Determine if a Policy has Excessive Permission?
      • How to Initiate Patch Remediation from CIEM Dashboard?
    • CSRM
      • How to Configure Automation Rule to Remediate Misconfigurations?
      • How to Create a Patching Task for Items Currently in “Approval Pending” State?
      • How to Evaluate Remediation Effort with Patching Impact Chart?
      • How to Prioritize and Address Older or High-Risk Anomalies with Patch Aging?
      • How to Monitor the Overall Status of the Remediation Job?
      • How do I Get to Know the Regions Impacted by a Specific Rule?
      • How to View the Severity of a Missing Patch Affected by a Rule?
      • How to Address Missing Patches Via Remediation Tasks?
      • How to Quickly Access the Necessary Tool for Remediation and Begin Patching Tasks?
    • CSAE
      • How to Setup Watchlist Configuration for a Resource?
      • How to Identify Outdated Resources for Cleanup?
      • How does Resource Categorization Work in Saner CSAE?
      • How to Identify Resources Exposed to External Network?
      • How to Understand the Resource Footprint Globally Across Various Regions?
      • How to Make Informed Decisions on Your Expenditure based on Resource Usage Graph?
    • CSPM
      • How to Setup Benchmarks in Saner CSPM?
      • How to Use Quick Evaluation Benchmarks?
      • How to Detect Patterns over a Period with Resource Trends?
      • How to Assess System Compliance and Security Posture?
    • CSPA
      • How to Initiate Patch Remediation from CSPA Dashboard?
      • How to Quickly Identify the Detected and Remediated Anomalies for an Account?
      • How to Prioritize Remediation or Fixes based on Confidence Levels?
      • How to Examine the Overall Anomaly Information for Specific Rules or Checks?
      • How to Search and Retrieve Anomaly Data?
      • How to Whitelist Rules or Resources in Cloud Security Scans?
  • Frequently Asked Questions
    • Saner Cloud Technical FAQs
  • Saner Cloud Release Notes
    • Saner Cloud – V.1.1 Release Notes
    • Saner Cloud – V.1.0 Release Notes
  • Security Intelligence for Saner Cloud
    • Infrastructure Entitlement Checks in AWS and Azure
      • Implementing Infrastructure Entitlement Checks in Azure
      • Implementing Infrastructure Entitlement Checks in AWS
    • Posture Anomaly Checks in AWS and Azure
      • Implementing Posture Anomaly Checks in AWS
      • Implementing Posture Anomaly Checks in Azure
    • Benchmark Compliance Rules in AWS and Azure
      • Implementing Benchmark Compliance Rules in Azure
      • Implementing PCI DSS 3 2 1 Regional in AWS
      • Implementing CIS 3 0 0 in AWS
      • Implementing HIPAA HITRUST Rules
      • Implementing PCI DSS 3 2 1 Global Rules in AWS
      • Implementing NIST 800 53 rev 5 Global Rules in AWS
      • Implementing SecPod Global Rules in AWS
      • Implementing CIS 3 0 0 Regional in AWS
      • Implementing CIS 4 0 0 Regional
      • Implementing SOC 2 in AWS
      • Implementing CIS 4 0 0 in AWS
      • Implementing NIST 800 53 rev 5 Rules in AWS
      • Implementing SecPod Regional Rules in AWS
      • Implementing SecPod Default Rules in AWS
      • Implementing NIST 800 53 rev 5 Regional in AWS
      • Implementing PCI DSS 3 2 1 in AWS
      • Implementing CIS 4 0 0 Global in AWS
      • Implementing CIS 3 0 0 Global Rules in AWS
      • Implementing SOC 2 Global Rules in AWS
      • Implementing SOC 2 Regional Rules in AWS

Saner CVEM

  • Saner CVEM Release Notes
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • SanerNow Risk Prioritization Launch
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
  • Saner CVEM Guide
    • What’s New in Saner CVEM?
    • Getting Started with Saner CVEM
    • Pre-requisites for Saner CVEM Deployment
    • How does Saner CVEM’s deployment architecture work?
  • Saner CVEM Products
    • Overview of Saner Continuous Vulnerability and Exposure Management
    • Saner CVEM Unified Dashboard User Guide
    • Saner CVEM Asset Exposure User Guide
    • Saner CVEM Continuous Posture Anomaly Management User Guide
    • Data Points IT teams can Fetch from Saner CPAM
    • Posture Anomaly Computation Rules
    • Saner CVEM Vulnerability Management User Guide
    • Saner CVEM Compliance Management User Guide
    • Saner CVEM Risk Prioritization User Guide
    • Saner CVEM Patch Management User Guide
    • Saner CVEM Endpoint Management User Guide
    • Saner CVEM Remote Access User Guide
    • Saner CVEM Network Scanner User Guide
    • Saner CVEM Cyber Hygiene Score User Guide
  • How Tos
    • Saner CPAM
      • How to create new response in PA tool?
      • How to build your own detection and response in PA tool?
      • How to whitelist an entire PA ID?
      • How to configure Posture Anomaly tool for custom detection?
      • How to fix Anomalies from PA dashboard?
      • How to fix anomalies detected in your account from All Anomalies Page?
      • How to fix anomalies from PA Summary page?
      • How to delete PA scan preferences?
      • How to schedule PA Scans on Daily, Weekly, and Monthly basis?
      • How to launch Posture Anomaly scans?
    • Saner AE
      • How to blacklist and whitelist applications in Saner AE?
      • How to manage asset licenses using Saner AE?
      • How to run an asset scan using Saner AE?
    • Saner VM
      • How to automate and schedule vulnerability scans?
      • How to exclude vulnerabilities in Saner VM tool
      • How to manage excluded vulnerabilities in Saner VM?
      • How to remediate vulnerabilities from vulnerability management dashboard?
    • Saner CM
      • How to run a compliance scan?
      • How to custom create a security policy?
      • How to align with PCI security compliance management?
      • How to align with NIST 800-171 security compliance management?
      • How to align with NIST 800-53 security compliance management?
      • How to align with HIPAA security compliance management using Saner CM?
    • Saner PM
      • How to fix firmware in Saner?
      • How to exclude patches in Saner PM?
      • How to manage excluded patches in Saner PM?
      • How to automate patch management in Saner PM?
      • How to roll back patches in Saner PM?
      • How to specify Service Level Agreement (SLA) using Remediation SLA in Saner PM?
      • How to apply missing patches in Saner PM?
      • How to apply the most critical patches in Saner PM?
      • How to perform custom remediation for applications that require paid patches using Saner PM
      • How to check the status of patching activity?
    • Saner EM
      • How to check wireless security in Windows systems?
      • How to collect all open ports in Windows systems?
      • How to check all firewall policies on Windows systems?
      • How to collect all the applications with an unknown publisher in Mac systems?
      • How to investigate DNS cache on Windows systems?
      • How to collect all the applications with an unknown publisher in Linux systems?
      • How to collect all software licenses in Windows systems?
      • How to collect environment variables set in all operating systems?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing Windows?
      • How to collect all families of operating systems such as Windows, Unix, and macOS?
      • How to collect all software licenses in Mac systems?
      • How to collect DNS information on Windows systems?
      • How to identify potentially unwanted programs such as torrent downloaders or unnecessary toolbars running on Windows systems?
      • How to collect all the applications with an unknown publisher in Windows systems?
      • How to collect all network interfaces in Windows systems?
      • How to collect a list of applications that are started when you boot your computer?
      • How to delete and quarantine a file?
      • How to collect mounted disk information on Linux systems?
      • How to check wireless signal quality in Windows systems?
      • How to perform system tuning?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing in Linux?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Linux systems?
      • How to collect DNS information on Linux systems?
      • How to check all firewall policies on Linux systems?
      • How to check wireless security in Linux systems?
      • How to check wireless signal quality in Linux systems?
      • How to collect all the important missing patches in Windows systems?
      • How to collect all installed patches in Windows systems?
      • How to collect all software patches that are hidden in the Windows Update server?
      • How to check the status of Windows Update Server (WSUS/SCCM)?
      • How to collect BIOS information such as serial number, version, manufacturer in Windows systems?
      • How to collect and investigate disk information on Windows systems?
      • How to investigate disks running out of space (<100 MB) in Windows systems?
      • How to collect operating systems information in Windows?
      • How to investigate total RAM or CPU threshold (greater than or equal to 80%) in Windows systems?
      • How to list all Groups in Windows systems?
      • How to collect all services that are currently running in Windows systems?
      • How to list all Administrator accounts on Windows systems?
      • How to list all guest accounts in Windows systems?
      • How to list all inactive users on Windows systems?
      • How to list last-logon details of users on Windows systems?
      • How to identify all users in Windows systems?
      • How to check if Bit-locker protection is OFF in Windows systems?
      • How to collect all keyboard and pointing devices connected to Windows systems?
      • How to collect all storage devices connected to Windows systems?
      • How to check account lockout policy on Windows systems?
      • How to check for Anti-Virus (AV) status in Windows systems?
      • How to check status of DEP in Windows systems?
      • How to check faulty Anti-Virus (AV) status in Windows systems?
      • How to check password policy set in Windows systems?
      • How to collect all security events from Windows Events Log?
      • How to start and stop the processes in Saner?
      • How to block blacklisted applications in Saner?
      • How to enable/disable devices in Saner
      • How to manually import devices into Saner?
      • How to deploy software in Saner EM?
      • How to enable and disable firewall settings in Saner AE?
      • How to collect all shared resources on Windows systems?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Windows systems?
      • How to connect to a client machine graphically using Saner Remote Access
  • FAQs
    • Saner CVEM Technical FAQs

Security Intelligence

  • Network Scanner Product Support Matrix
  • Privilege levels for authenticated scans using Saner Network Scanner
  • Overview of Security Content and Intelligence
  • Security Content Statistics
  • Application and OS Remediation Coverage
  • Compliance Benchmark Coverage
  • List of Vulnerability to Exploit/Malware Mapping covered in Saner
  • OVAL Definitions Family-wise Distribution
  • OVAL Definitions Class-wise Distribution
  • OVAL Definitions Platform Coverage
View Categories
  • Home
  • Docs
  • Saner Cloud
  • Get Started
  • Roles and Permissions
  • Roles and Permissions for AWS Remediation Access

Roles and Permissions for AWS Remediation Access

Print Friendly, PDF & Email

The following table outlines the permissions granted for various AWS resources. It includes multiple AWS services, such as IAM (management of users, groups, and roles), EC2 (virtual servers and networking), S3 (storage), CloudFront, CloudTrail, and others.

ActionWebservicePermissionDescription
EnableDomainAutoRenewroute53domainsAllowAutomatically renew the specified domain before the domain registration expires
 
Click here to read more…
EnableDomainTransferLockroute53domainsAllowSets the transfer lock on the domain (specifically the clientTransferProhibited status) to prevent domain transfers
 
Click here to read more…
CreateClusterredshiftAllowCreate an EKS cluster
 
Click here to read more…
ModifyClusterredshiftAllowModifies the number of steps that can be executed concurrently for the cluster specified using ClusterID
 
Click here to read more…
CreateTrailcloudtrailAllowCreates a trail that specifies the settings for delivery of log data to an Amazon S3 bucket
 
Click here to read more…
PutEventSelectorscloudtrailAllowConfigures event selectors or advanced event selectors for your trail
 
Click here to read more…
UpdateTrailcloudtrailAllowUpdates trail settings that control what events you are logging, and how to handle log files
Click here to read more…
StartLoggingcloudtrailAllowStarts the recording of AWS API calls and log file delivery for a trail
 
Click here to read more…
SetQueueAttributesSQSAllowSets the value of one or more queue attributes, like a policy
 
Click here to read more…
PutMetricFilterLogsAllowCreates or updates a metric filter and associates it with the specified log group
 
Click here to read more…
CreateLogGroupLogsAllowCreates a log group with the specified name
 
Click here to read more…
UpdateDistributionCloudfrontAllowUpdates the configuration for a CloudFront distribution
 
Click here to read more…
CreateTopicSNSAllowCreates a topic to which notifications can be published
 
Click here to read more…
SubscribeSNSAllowSubscribes an endpoint to an Amazon SNS topic
 
Click here to read more…
CreateLoadBalancerPolicyElasticloadbalancingAllowCreates a policy with the specified attributes for the specified load balancer
 
Click here to read more…
SetLoadBalancerPoliciesOfListenerElasticloadbalancingAllowReplaces the current set of policies for the specified load balancer port with the specified set of policies
 
Click here to read more…
CreateLoadBalancerListenerselasticloadbalancingAllowCreates one or more listeners for the specified load balancer
 
Click here to read more…
ModifyLoadBalancerAttributesElasticloadbalancingAllowModifies the attributes of the specified load balancer
 
Click here to read more…
UpdateCertificateOptionsacmAllowUpdates a certificate
 
Click here to read more…
DeleteCertificateacmAllowDeletes a certificate and its associated private key. 
 
Click here to read more…
ImportCertificateacmAllowImports a certificate into AWS Certificate Manager (ACM) to use with services
 
Click here to read more…
RemoveUserFromGroupIAMAllowRemoves the specified user from the specified group.
 
Click here to read more…
UpdateAccessKeyIAMAllowChanges the status of the specified access key from Active to Inactive, or vice versa. 
 
Click here to read more…
DetachUserPolicyIAMAllowRemoves the specified policy from the specified user.
 
Click here to read more…
DeletePolicyIAMAllowDeletes the specified policy.
 
Click here to read more…
PutRolePolicyIAMAllowAdds or updates an inline policy document
 
Click here to read more…
DeleteUserIAMAllowDeletes the specified user from the group
 
Click here to read more…
DetachGroupPolicyIAMAllowRemoves the specified policy from the specified group
 
Click here to read more…
DeletePolicyVersionIAMAllowDeletes the specified version from the specified policy
 
Click here to read more…
DeleteRolePolicyIAMAllowDeletes the specified inline policy that is embedded in the specified role.
 
Click here to read more…
CreateLoginProfileIAMAllowCreates a password for the specified IAM user.
 
Click here to read more…
UpdateUserIAMAllowUpdates the name and/or the path of the specified user
 
Click here to read more…
DeleteLoginProfileIAMAllowDeletes the password for the specified user
 
Click here to read more…
PutUserPolicyIAMAllowAdds or updates an inline policy document that is embedded in the specified user.
 
Click here to read more…
DetachRolePolicyIAMAllowRemoves the specified policy from the specified role.
Click here to read more…
CreateVirtualMfaDeviceIAMAllowCreates a new virtual MFA device for the AWS account. 
 
Click here to read more…
EnableMfaDeviceIAMAllowEnables the specified MFA device and associates it with the specified user. 
 
Click here to read more…
CreatePolicyIAMAllowCreates a new policy for your AWS account.
 
Click here to read more…
UpdateAccountPasswordPolicyIAMAllowUpdates the password policy settings for the AWS account
 
Click here to read more…
CreateRoleIAMAllowCreates a new role for your AWS account.
 
Click here to read more…
AddUserToGroupIAMAllowAdds the specified user to the specified group.
 
Click here to read more…
DeleteAccessKeyIAMAllowDeletes the access key pair associated with the specified user.
 
Click here to read more…
AttachUserPolicyIAMAllowAttaches the specified policy to the specified user.
 
Click here to read more…
CreatePolicyVersionIAMAllowCreates a new version of the specified policy
PutGroupPolicyIAMAllowAdds or updates an inline policy document that is embedded in the specified group.
 
Click here to read more…
DeleteRoleIAMAllowDeletes the specified role
 
Click here to read more…
UpdateLoginProfileIAMAllowChanges the password for the specified user.
 
Click here to read more…
DeleteGroupPolicyIAMAllowDeletes the specified inline policy that is embedded in the specified IAM group
 
Click here to read more…
RemoveRoleFromInstanceProfileIAMAllowRemoves the specified role from the specified Amazon EC2 instance profile
 
Click here to read more…
CreateAccessKeyIAMAllowCreates a new AWS secret access key and corresponding AWS access key ID for the specified user
 
Click here to read more…
AttachGroupPolicyIAMAllowAttaches the specified managed policy to the specified group
 
Click here to read more…
DeleteGroupIAMAllowDeletes the specified group
 
Click here to read more…
DeleteUserPolicyIAMAllowDeletes the specified inline policy that is embedded in the specified user
 
Click here to read more…
AttachRolePolicyIAMAllowAttaches the specified managed policy to the specified IAM role
CreateDBSnapshotRDSAllowCreates a snapshot of a DB instance.
 
Click here to read more…
CopyDBSnapshotRDSAllowCopies the specified DB snapshot
 
Click here to read more…
RestoreDBInstanceFromDBSnapshotRDSAllowCreates a new DB instance from a DB snapshot
 
Click here to read more…
DeleteDBInstanceRDSAllowDeletes a previously provisioned DB instance.
 
Click here to read more…
ModifyDBInstanceRDSAllowModifies settings for a DB instance. 
 
Click here to read more…
StartConfigurationRecorderConfigAllowStarts the customer managed configuration recorder
 
Click here to read more…
PutConfigurationRecorderConfigAllowCreates or updates the customer managed configuration recorder
 
Click here to read more…
PutDeliveryChannelConfigAllowCreates or updates a delivery channel to deliver configuration information and other compliance information
 
Click here to read more
UpdateTerminationProtectionCloudformationAllowUpdates termination protection for the specified stack
 
Click here to read more
EnableAlarmActionsCloudWatchAllowEnables the actions for the specified alarms
 
Click here to read more…
PutMetricAlarmCloudWatchAllowCreates or updates an alarm and associates it with the specified metric, metric math expression, anomaly detection model, or Metrics Insights query
 
Click here to read more…
ResetImageAttributeEC2AllowResets an attribute of an AMI to its default value
 
Click here to read more…
CreateVolumeEC2AllowCreates an EBS volume that can be attached to an instance in the same Availability Zone
 
Click here to read more…
DisassociateAddressEC2AllowDisassociates an Elastic IP address from the instance or network interface it’s associated with
 
Click here to read more…
ModifyInstanceMaintenanceOptionsEC2AllowModifies the recovery behavior of your instance to disable simplified automatic recovery or set the recovery behavior to default
 
Click here to read more…
RunInstancesEC2AllowLaunches the specified number of instances using an AMI for which you have permissions.
 
Click here to read more…
AuthorizeSecurityGroupEgressEC2AllowAdds the specified outbound (egress) rules to a security group
 
Click here to read more…
CopySnapshotEC2AllowCopies a point-in-time snapshot of an EBS volume and stores it in Amazon S3. 
 
Click here to read more…
ModifySnapshotAttributeEC2AllowAdds or removes permission settings for the specified snapshot. 
 
Click here to read more…
RevokeSecurityGroupEgressEC2AllowRemoves the specified outbound (egress) rules from the specified security group.
 
Click here to read more…
AuthorizeSecurityGroupIngressEC2AllowAdds the specified inbound (ingress) rules to a security group.
 
Click here to read more…
MonitorInstancesEC2AllowEnables detailed monitoring for a running instance
 
Click here to read more…
DeleteNetworkAclEC2AllowDeletes the specified network ACL
 
Click here to read more…
RevokeSecurityGroupIngressEC2AllowRemoves the specified inbound (ingress) rules from a security group
 
Click here to read more…
ModifyInstanceAttributeEC2AllowModifies the specified attribute of the specified instance.
 
Click here to read more…
DeleteSecurityGroupEC2AllowIf you attempt to delete a security group that is associated with an instance or network interface, is referenced by another security group in the same VPC, or has a VPC association, the operation fails with DependencyViolation
 
Click here to read more…
ModifyImageAttributeEC2AllowModifies the specified attribute of the specified AMI.
 
Click here to read more…
CreateSnapshotEC2AllowCreates crash-consistent snapshots of multiple EBS volumes attached to an Amazon EC2 instance.
 
Click here to read more…
DetachVolumeEC2AllowDetaches an EBS (Elastic Block Store) volume from an instance
 
Click here to read more…
CreateRouteEC2AllowCreates a route in a route table within a VPC
 
Click here to read more…
CreateFlowLogsEC2AllowCreates one or more flow logs to capture information about IP traffic for a specific network interface, subnet, or VPC
 
Click here to read more…
CreateFlowLogsEC2AllowCreates one or more flow logs to capture information about IP traffic for a specific network interface, subnet, or VPC
 
Click here to read more…
StartInstancesEC2AllowStarts an Amazon EBS-backed instance that you’ve previously stopped
 
Click here to read more…
ModifySecurityGroupRulesEC2AllowModifies the rules of a security group.
 
Click here to read more…
CreateImageEC2AllowCreates an Amazon EBS-backed AMI from an Amazon EBS-backed instance that is either running or stopped.
 
Click here to read more…
DeleteRouteEC2AllowDeletes the specified route from the specified route table
 
Click here to read more…
TerminateInstancesEC2AllowShuts down the specified instances. 
 
Click here to read more…
DeleteSnapshotEC2AllowDeletes the specified snapshot
 
Click here to read more…
AttachVolumeEC2AllowAttaches an EBS volume to a running or stopped instance and exposes it to the instance with the specified device name
 
Click here to read more…
StopInstancesEC2AllowStops an Amazon EBS-backed instance.
 
Click here to read more…
DeregisterImageEC2AllowDeregisters the specified AMI. After you deregister an AMI, it can’t be used to launch new instances.
 
Click here to read more…
CreateSecurityGroupEC2AllowA security group acts as a virtual firewall for your instance to control inbound and outbound traffic
 
Click here to read more…
CreateBucketS3AllowThis action creates an Amazon S3 bucket
 
Click here to read more…
PutBucketPublicAccessBlockS3AllowCreates or modifies the PublicAccessBlock configuration for an Amazon S3 bucket
 
Click here to read more…
PutBucketPolicyS3AllowApplies an Amazon S3 bucket policy to an Amazon S3 bucket
 
Click here to read more…
PutEncryptionConfigurationS3AllowThis operation configures default encryption and Amazon S3 Bucket Keys for an existing bucket.
 
Click here to read more…
PutBucketLoggingS3AllowSet the logging parameters for a bucket and to specify permissions for who can view and modify the logging parameters
 
Click here to read more…
PutBucketVersioningS3AllowSets the versioning state of an existing bucket.
 
Click here to read more…
ModifyListenerelasticloadbalancingAllowReplaces the specified properties of the specified listener
 
Click here to read more…
CreateListenerelasticloadbalancingAllowCreates a listener for the specified Application Load Balancer, Network Load Balancer, or Gateway Load Balancer
 
Click here to read more…

Share This Article :
  • X
  • LinkedIn
Still stuck? How can we help?

Saner Documentation Feedback

Copyright 2025 - SecPod. All Rights Reserved. Privacy Policy.
SanerNow Version 6.3.x